VDB

GCVE-VVD-NCSC-2025-381

GCVE-VVD-NCSC-2025-381
Advisory PublishedCVSS 3.5/10
Vulnetix · Advisory published December 8, 2025
A vulnerability in specific versions of Splunk Enterprise and Splunk Cloud Platform allows low-privileged users to create a views dashboard with a custom background, potentially leading to unvalidated redirects to malicious external sites.

Weaknesses (CWE)

CWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-117Improper Output Neutralization for LogsCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-732Incorrect Permission Assignment for Critical ResourceCWE-918Server-Side Request Forgery (SSRF)CWE-20Improper Input Validation

Risk Scores

CVSS 3.1
3.5/10
Low · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Splunkvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›